4 ms·
A bit of background on this (I am involved in the ultrasound industry): - The chip Samsung uses is by Qualcomm. Their big claim is that their ultrasound finger
by tompccs 7y ago
A bit of background on this (I am involved in the ultrasound industry):
- The chip Samsung uses is by Qualcomm. Their big claim is that their ultrasound fingerprint scanner is the only US government approved non-optical way of electronically scanning a fingerprint (those sensors they have at airports use basically the same technology)
- It's supposed to be more secure than the capacitive technology Apple used to use since it grabs a true image of the fingerprint and not just a low-res representation
- Given this, it's probably a problem with the software on Samsung's part, not Qualcomm
- However, it's interesting that adding the screen protector is what broke it. It suggests that there could be any number of unintentional biometric security holes
- It demonstrates that consumer tech companies (with possible exception of Apple) don't really have the expertise or motivation to properly implement biometric authentication
(edit - newlines)
- nolok 7y agoEdit: I was wrong and misunderstood the article
- number_six 7y agoThis is not true. Here you can watch someone set up the fingerprint without the protection and using a different finger to unlock it after the protection: https://twitter.com/Sta_Light_/status/1184475413252210688 https://twitter.com/Sta_Light_/status/1184475413252210688
- criddell 7y agoIs Samsung actually storing a hi res copy of a fingerprint, or just a hash? I'm not sure I want any tech company storing high resolution scans of my biometrics.
- jimmaswell 7y agoIs it not only stored on the device's secure storage, not online?
- criddell 7y agoThere really isn't a good reason to store it at all though, is there?
- tompccs 7y agoOfficially, they only store a hash, but this is only a software restriction - I believe it is possible to obtain full images but this may not be possible with the public APIs. In practice it may be possible to reverse-engineer the stored hashes but this has not been demonstrated (yet).
- afandian 7y agoWhat kind of hash is used? I guess it has to be some kind of inexact match (I doubt the fingerprint image is ever exactly the same)? Does it operate over the image of the fingerprint or a vector of extracted features?
- OkGoDoIt 7y agoYeah, I never understood how you could hash fingerprints or face unlock data. How do you do a fuzzy match on a hash? I guess you can make the original data less detailed/precise, such that slight variations would still come out with the same hash, but that seems to defeat some of the security.
- setr 7y agopresumably you would hash many variations of the initial thumbprint, and then simply compare the new thumbprint hash against the list of possibilities, passing upon finding the first match
- lttlrck 7y agoPerhaps it’s similar to how Shazam fingerprints music. It’s a fingerprint of a fingerprint so to speak.
- MiroF 7y agohttps://en.wikipedia.org/wiki/Locality-sensitive_hashing https://en.wikipedia.org/wiki/Locality-sensitive_hashing
- SlowRobotAhead 7y agoI’m curious if they can store a hash of a print. What I know about prints is that you’re looking for some number of correlations between features. So of 90 points from the first scan, you’ll need 16 to match on entry. So... I don’t think without knowing which 16-90 points you’re going to compare that you can hash all the combinations. I could be wrong, but I suspect this is something they don’t JUST hash.
- sildur 7y agoThis is how Apple does it: The fingerprint sensor is active only when the capacitive steel ring that surrounds the Home button detects the touch of a finger, which triggers the advanced imaging array to scan the finger and send the scan to the Secure Enclave. Communication between the processor and the Touch ID sensor takes place over a serial peripheral interface bus. The processor forwards the data to the Secure Enclave but can’t read it. It’s encrypted and authenticated with a session key that is negotiated using a shared key provisioned for each Touch ID sensor and its corresponding Secure Enclave at the factory. The shared key is strong, random, and different for every Touch ID sensor. The session key exchange uses AES key wrapping with both sides providing a random key that establishes the session key and uses AES-CCM transport encryption. The raster scan is temporarily stored in encrypted memory within the Secure Enclave while being vectorized for analysis, and then it’s discarded. The analysis utilizes sub dermal ridge flow angle mapping, which is a lossy process that discards minutia data that would be required to reconstruct the user’s actual fingerprint. The resulting map of nodes is stored without any identity information in an encrypted format that can only be read by the Secure Enclave. This data never leaves the device. It isn’t sent to Apple, nor is it included in device backups.
- vernie 7y agoCan you elaborate on the operating principle behind the ultrasonic sensor what makes its output a "true image" vs. Touch ID's "low-res representation"?
- Havoc 7y ago>It demonstrates that consumer tech companies (with possible exception of Apple) don't really have the expertise I suspect Samsung can muster a fair bit of expertise if they feel the need. We're not exactly talking about a fly-by-night tech startup here...
- theclaw 7y agoYeah agreed. It's almost certainly some code that needs to change from this: testResult = TestFingerprint(fingerprint); if(testResult) return UNLOCK_OK; else return UNLOCK_FAIL; to this: testResult = TestFingerprint(fingerprint); if(testResult == RESULT_OK) return UNLOCK_OK; else return UNLOCK_FAIL;
- mfgs 7y agoThat seems unlikely. They surely would've done the most basic testing that would've found a bug like that. The issue here seems to be the addition of the screen cover is making all fingerprints appear similar enough to pass as the same one.
- kalleboo 7y agoMy initial guess was something like the fingerprint is stored as a bunch of samples of where there are "hills" on the finger, and verifying the fingerprint consisted of checking that those hills are present - another human will have valleys where the first person had hills. The gel screen protector presented 100% hills so all the checks passed. What they needed to fix was to check for the non-presence of some "valleys" as well. Of course the fact that they're using hashes of the fingerprint means this theory is bogus and the issue is probably a lot more complex/involved.